ADOdb PostgreSQL SQL Injection Vulnerability
BID:16364
Info
ADOdb PostgreSQL SQL Injection Vulnerability
| Bugtraq ID: | 16364 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-0410 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 24 2006 12:00AM |
| Updated: | Apr 17 2006 08:32PM |
| Credit: | Andy Staudacher is credited with the discovery of this vulnerability. |
| Vulnerable: |
PHP Link Directory PHPLD 2.0 Gentoo Linux Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 Debian Linux 3.0 sparc Debian Linux 3.0 s/390 Debian Linux 3.0 ppc Debian Linux 3.0 mipsel Debian Linux 3.0 mips Debian Linux 3.0 m68k Debian Linux 3.0 ia-64 Debian Linux 3.0 ia-32 Debian Linux 3.0 hppa Debian Linux 3.0 arm Debian Linux 3.0 alpha Debian Linux 3.0 ADOdb ADOdb 4.70 ADOdb ADOdb 4.68 ADOdb ADOdb 4.66 |
| Not Vulnerable: |
ADOdb ADOdb 4.71 |
Discussion
ADOdb PostgreSQL SQL Injection Vulnerability
ADOdb is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
This issue affects only ADOdb implementations using PostgreSQL; other databases are not affected.
ADOdb is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
This issue affects only ADOdb implementations using PostgreSQL; other databases are not affected.
Exploit / POC
ADOdb PostgreSQL SQL Injection Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
ADOdb PostgreSQL SQL Injection Vulnerability
Solution:
The vendor has released an update addressing this issue. Please see the referenced vendor advisories for further information.
ADOdb ADOdb 4.66
ADOdb ADOdb 4.68
ADOdb ADOdb 4.70
Solution:
The vendor has released an update addressing this issue. Please see the referenced vendor advisories for further information.
ADOdb ADOdb 4.66
-
ADOdb adodb471.zip
http://prdownloads.sourceforge.net/adodb/adodb471.zip
ADOdb ADOdb 4.68
-
ADOdb adodb471.zip
http://prdownloads.sourceforge.net/adodb/adodb471.zip
ADOdb ADOdb 4.70
-
ADOdb adodb471.zip
http://prdownloads.sourceforge.net/adodb/adodb471.zip
References
ADOdb PostgreSQL SQL Injection Vulnerability
References:
References:
- ADOdb Lite Homepage (ADOdb)
- Bug for libs in php link directory (PHP Link Directory)
- Release Name: adodb-4.71-for-php (ADOdb)
- Bug for libs in php link directory 2.0 (Mario Oyorzabal Salgado
)